First published: Fri Dec 12 2008(Updated: )
The XSS Filter in Microsoft Internet Explorer 8.0 Beta 2 allows remote attackers to bypass the XSS protection mechanism and conduct XSS attacks by injecting data at two different positions within an HTML document, related to STYLE elements and the CSS expression property, aka a "double injection."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Internet Explorer | =8-beta2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-5551 is classified as a high severity vulnerability due to its potential impact on web application security.
CVE-2008-5551 allows XSS attacks by bypassing the XSS protection in Internet Explorer 8.0 Beta 2 through double injection of data within HTML documents.
CVE-2008-5551 specifically affects Microsoft Internet Explorer 8.0 Beta 2.
Mitigation for CVE-2008-5551 involves upgrading to a later, secure version of Internet Explorer that does not include this vulnerability.
Yes, remote attackers can exploit CVE-2008-5551 to conduct cross-site scripting (XSS) attacks by injecting malicious scripts.